diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml index 74593165dd..c63ba3662c 100644 --- a/.github/workflows/trivy.yml +++ b/.github/workflows/trivy.yml @@ -72,15 +72,19 @@ jobs: # branch: update-vulnerabilities # base: master - - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@0.20.0 - with: - scan-type: 'fs' - target: '/home/runner/work/hale/hale' # specify the target directory or file - format: 'sarif' - output: 'trivy-results.sarif' - severity: 'CRITICAL,HIGH' - debug: true + - name: Run Trivy scan + run: | + trivy fs --target /home/runner/work/hale/hale --debug --format sarif --output trivy-results.sarif + + #- name: Run Trivy vulnerability scanner + # uses: aquasecurity/trivy-action@0.20.0 + # with: + # scan-type: 'fs' + # target: '/home/runner/work/hale/hale' + # format: 'sarif' + # output: 'trivy-results.sarif' + # severity: 'CRITICAL,HIGH' + # debug: true - name: Upload Trivy scan results to file uses: actions/upload-artifact@v2